Privacy Policy

Last updated: 13 August 2026

This document describes what data VilyQ processes, where it is stored and who else has access to it. It is written to be verifiable rather than reassuring.

Who processes the data

VilyQ is a platform used by a distribution company (the “customer”) to manage its field sales team. For the data the customer enters — its locations, employees and sales — the customer is the data controller and VilyQ is a processor acting only on its instructions. For the customer's own account data (name, email, billing) VilyQ is the controller.

What data is processed

Account: name, email, role, language. Locations: customer name and company, address, coordinates, phone, company ID, VAT number, responsible person. Field work: visits with date and time, GPS coordinates and a photo (only if the company enabled GPS validation), sales with items and quantities, orders, invoices, stock movements. Technical: IP address and browser data in hosting logs, error reports.

Where it is stored

The database runs in AWS Frankfurt, Germany (eu-central-1). The application's server code runs on Vercel Frankfurt (fra1). Both are within the European Union. Files (visit photos, documents) are kept in the same infrastructure.

Separation between customers

Separation is not performed by application code but by the database itself. Each of the 42 tables has row level security enabled, with 122 rules in total binding access to the user's company. Even if the application had a bug, a query for another company's data is refused by the database. Within a company access narrows further: a sales rep sees their own locations, a regional manager their region.

What KriQ receives

KriQ is the analysis feature in the product and runs through Anthropic (USA). It receives only already-computed aggregate figures for that specific company: location and employee names, revenue for a period, visit counts, days since the last visit, trends. It does not receive raw database rows, does not receive another company's data, and database permissions remain its ceiling — it sees exactly what the person asking sees. Actions that change data are never executed automatically: KriQ proposes, a person confirms.

Security

Traffic is encrypted (TLS) and data is encrypted at rest. Passwords are not stored by VilyQ — they are handled by Supabase Auth and kept only as an irreversible hash. Sensitive actions are written to an audit log recording who, what and when: issuing an invoice, approving and rejecting an order, changing roles. Permissions are managed through per-module roles rather than job titles.

Access by VilyQ

VilyQ staff have technical access to the infrastructure for support and troubleshooting. That access is used only for a specific reason. VilyQ does not sell data and does not provide it to third parties for marketing purposes.

Retention

Data is kept while the contract is active. After termination it is retained for up to 60 days so that recovery is possible in case of error or dispute, and then deleted. The customer may request earlier deletion in writing. Documents with tax significance (invoices) are kept for the statutory period regardless of termination.

Data subject rights

Every individual has the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object. Where VilyQ acts as a processor, requests are addressed to the company using the platform and VilyQ assists. For data where VilyQ is the controller, write to the address below.

Changes

If this policy changes materially, we notify customers by email before the change takes effect.

Sub-processors

These providers process data on VilyQ's behalf. The list is updated when it changes.

SupabaseDatabase, authentication, filesEU — Frankfurt
VercelApplication hostingEU — Frankfurt
AnthropicKriQ — analysis over aggregate figuresUSA
StripeSubscription paymentsEU / USA

Contact

Questions about this policy and data access requests: demo@vilyq.com